用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/trycompai/comp --skill audit-hooks命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
Run all audit checks (RBAC, hooks, design system, tests) and verify build
Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it ships. Use after editing any API controller, guard, or auth code (apps/api/src/auth/**), a Prisma schema/query, a file-upload/webhook handler, or before committing/pushing security-sensitive changes.
How to reuse ANY integration check's results in a feature via the universal CheckResultsService (apps/api integration-platform). Use whenever a feature needs data produced by an integration check — "show 2FA status on People", "surface AWS S3 findings in X", "reuse a check's results", "per-user/per-resource results from a connected integration", "which integrations feed task T". Read this BEFORE writing your own IntegrationCheckResult / CheckRunRepository query — don't hand-roll it.
基于 SOC 职业分类
| name | audit-hooks |
| description | Audit & fix hooks and API usage patterns — eliminate server actions, raw fetch, and stale patterns |
Audit the specified files for hook and API usage compliance. Fix every issue found immediately.
useAction from next-safe-action → replace with SWR hook or custom mutation hook@db → delete and use API hook instead@db in client components → replace with apiClient via hook@db in Next.js pages for mutations → replace with serverApifetch() without credentials: 'include' → use apiClientwindow.location.reload() after mutations → use SWR mutate()router.refresh() after mutations → use SWR mutate()useEffect + apiClient.get for data fetching → replace with useSWRonXxxAdded, onSuccess) → remove, rely on SWR cache sharinguseSWR with apiClient or custom hookapiClient with mutate() for cache invalidationserverApi from apps/app/src/lib/api-server.tsfallbackData for SSR data, revalidateOnMount: !initialDataresponse.data.data, single = response.datamutate() safety: guard against undefined in optimistic update functionsArray.isArray() checks: when consuming SWR data that could be stale$ARGUMENTSbunx turbo run typecheck --filter=@trycompai/app